We adhere to high security standards
The security of your data is very important to us, which is why we follow strict security measures. Development, data storage, and AI inference take place entirely in Germany and are not subject to the U.S. Cloud Act.
Security
Operations and data residency
Your instance runs separately from all other customers. Development, data storage, and AI inference take place exclusively in Germany. Upon request, we can also operate your instance in your own data center; however, we recommend that we manage it, as you’ll then receive updates immediately and won’t carry any maintenance burden.
Access and sign-in
Accounts are created by your administrators only. There is no self-registration, no social logins and no shared accounts. TOTP two-factor authentication can be enforced across the entire instance, and passkeys (WebAuthn/FIDO2) can replace the password entirely where you want that. Signing out or disabling an account takes effect immediately on every device, because sessions are checked server-side on every request. On request we connect your corporate sign-in over OpenID Connect.
Encryption and deletion
Each user has their own data key: content is stored in encrypted form in the database, file storage, and search index. If the key is deleted, all of that user’s data becomes permanently unreadable. This is how we implement the right to erasure under Article 17 of the GDPR. Conversations and uploaded files are automatically deleted after 90 days (configurable) of inactivity.
Traceability
We maintain a comprehensive audit log that provides a traceable record of relevant user actions on the platform. This log can be viewed by your administrator. In addition, regular backups are performed to ensure that your data is not lost even in the event of critical errors.
Where your instance runs
Every customer gets a dedicated instance, separated from every other. We run it in Germany and recommend exactly that – but running it in your own data center is possible where your own policies require it.
A dedicated instance, operated by us
RecommendedYour instance runs in Germany, separated from every other customer. Updates and new features reach you the moment they are ready, and the maintenance work stays with us rather than with your IT team.
Running it in your own data center
If your requirements call for on-premises operation, this can be set up. The details can be agreed upon during the initial consultation.
The mechanisms in detail
Web search through a European service
Web search runs through a European search service. What is transmitted is your query text – and, where the AI is asked to read one specific page, that page’s hostname together with a query derived from its address. No user identifiers, no cookies, no correlation IDs.
Integrations carry the user’s own permissions
Each employee links their own account. An agent works with these login credentials and thus sees exactly what the person is authorized to see – never through a shared account. Login credentials are encrypted for each user and cannot be viewed by us or by an administrator.
Code execution with no network access
AI-generated code runs in an isolated sandbox with no internet access and no access to the database or the search index.
Your content is never used for training
Neither we nor the subprocessors we use apply your inputs or the generated answers to train or improve AI models. We commit to that contractually.
Frequently asked questions
Does our data ever leave Germany?
Development, data storage and AI inference all happen in Germany. For web search, your query text is transmitted to a European search service – and, where the AI is asked to read one specific page, that page’s hostname together with a query derived from its address. Every processor involved appears in the list of subprocessors you receive before signing.
Can we run Intra AI in our own data center?
Yes, that is possible. It is not what we recommend, though: every customer gets a dedicated instance, separated from every other, that we run in Germany. That way updates and new features reach you the moment they ship, and the maintenance work stays with us rather than with your IT team. If your own policies require running it in-house, we will set that up – talk to us and we will go through the requirements together.
How quickly does revoking access take effect?
Immediately. Every session is bound to a server-side record that is checked on each request. Signing out all devices or disabling an account takes effect at once, not when a token happens to expire.
Let’s work through your IT requirements
Bring your security requirements or your IT department’s questionnaire. We will go through it in the intro call and say, line by line, whether we meet it or not.